TOGAF TOGAF Security and Risk Architecture 2 — Questions and Answers
Question 1: What is a 'Risk Register' in the context of TOGAF architecture governance?
- A list of approved risk management software tools
- A document capturing identified risks, their classification, mitigation strategies, and ownership throughout the architecture lifecycle (Correct answer)
- A financial instrument for risk transfer
- A register of security vulnerabilities
Correct answer: A document capturing identified risks, their classification, mitigation strategies, and ownership throughout the architecture lifecycle
The Risk Register is a governance artifact capturing all identified risks to the architecture, with their classification, probability, impact, mitigation approaches, and responsible owners.
Question 2: In TOGAF, how does security architecture relate to the concept of 'Architecture Building Blocks'?
- Security building blocks are purchased from vendors only
- Security capabilities can be defined as Architecture Building Blocks (ABBs) and implemented as Solution Building Blocks (SBBs) for reuse (Correct answer)
- Security is not represented as building blocks
- Building blocks only apply to technology infrastructure, not security
Correct answer: Security capabilities can be defined as Architecture Building Blocks (ABBs) and implemented as Solution Building Blocks (SBBs) for reuse
Security capabilities (e.g., identity management, encryption services) can be defined as ABBs specifying the required capability and then implemented as SBBs representing specific products.
Question 3: What is the purpose of a 'Security Architecture View' in TOGAF?
- To document security team organizational structure
- To communicate the security architecture to security-focused stakeholders by addressing their specific security concerns (Correct answer)
- To list all security vulnerabilities
- To document IT audit findings
Correct answer: To communicate the security architecture to security-focused stakeholders by addressing their specific security concerns
A Security Architecture View addresses the concerns of security-focused stakeholders, showing how security requirements and controls are incorporated across the architecture domains.
Question 4: How does TOGAF recommend integrating compliance requirements (e.g., regulatory, legal) into the architecture?
- Compliance is handled by the legal team separately from architecture
- Compliance requirements should be captured as architecture requirements and constraints early in the ADM, influencing architecture decisions (Correct answer)
- Compliance only affects the Technology Architecture domain
- Compliance is addressed only after the architecture is fully defined
Correct answer: Compliance requirements should be captured as architecture requirements and constraints early in the ADM, influencing architecture decisions
TOGAF recommends treating regulatory and compliance requirements as architecture constraints captured early in the ADM (Phase A/B) so they influence all subsequent architecture decisions.
Question 5: What does the TOGAF concept of 'Security Zoning' contribute to Technology Architecture design?
- Defining time zones for global IT operations
- Segmenting the technology environment into zones with different trust levels and controlling inter-zone traffic (Correct answer)
- Allocating server rack space in data centers
- Defining IT department organizational boundaries
Correct answer: Segmenting the technology environment into zones with different trust levels and controlling inter-zone traffic
Security Zoning divides the technology architecture into trust zones (e.g., DMZ, internal, restricted) with defined controls on traffic between zones, a key element of Technology Architecture.
Question 6: In TOGAF, what is the relationship between 'Architecture Principles' and security constraints during Phase B (Business Architecture)?
- Architecture Principles do not apply to Business Architecture
- Security-related Architecture Principles constrain what business processes and capabilities can be designed in Phase B (Correct answer)
- Business Architecture ignores security until Phase D
- Principles are only relevant for technology decisions
Correct answer: Security-related Architecture Principles constrain what business processes and capabilities can be designed in Phase B
Security-related Architecture Principles apply from Phase B onwards, constraining business process design to ensure inherent security is considered in business architecture decisions.
What is a 'Risk Register' in the context of TOGAF architecture governance?